ModSecurity is a potent web application layer firewall for Apache web servers. It monitors the whole HTTP traffic to a website without affecting its operation and when it identifies an intrusion attempt, it prevents it. The firewall additionally maintains a more detailed log for the website visitors than any server does, so you will manage to monitor what's going on with your sites much better than if you rely merely on conventional logs. ModSecurity works with security rules based on which it prevents attacks. For example, it recognizes whether anyone is trying to log in to the admin area of a specific script a number of times or if a request is sent to execute a file with a particular command. In these situations these attempts trigger the corresponding rules and the firewall blocks the attempts in real time, after that records in-depth information about them within its logs. ModSecurity is among the best software firewalls out there and it could easily protect your web applications against many threats and vulnerabilities, particularly in case you don’t update them or their plugins frequently.

ModSecurity in Shared Hosting

We offer ModSecurity with all shared hosting solutions, so your web apps will be shielded from malicious attacks. The firewall is switched on by default for all domains and subdomains, but if you would like, you will be able to stop it through the respective part of your Hepsia Control Panel. You could also activate a detection mode, so ModSecurity will keep a log as intended, but shall not take any action. The logs which you'll discover inside Hepsia are very detailed and offer info about the nature of any attack, when it occurred and from what IP, the firewall rule which was triggered, and so on. We use a group of commercial rules which are often updated, but sometimes our administrators include custom rules as well in order to better protect the websites hosted on our servers.

ModSecurity in Semi-dedicated Hosting

Any web app which you install within your new semi-dedicated hosting account will be protected by ModSecurity because the firewall comes with all our hosting plans and is activated by default for any domain and subdomain that you add or create using your Hepsia hosting Control Panel. You shall be able to manage ModSecurity via a dedicated area within Hepsia where not simply could you activate or deactivate it completely, but you could also activate a passive mode, so the firewall shall not block anything, but it'll still maintain a record of possible attacks. This requires just a mouse click and you shall be able to view the logs regardless if ModSecurity is in active or passive mode through the same section - what the attack was and where it came from, how it was addressed, etc. The firewall uses two groups of rules on our servers - a commercial one that we get from a third-party web security provider and a custom one that our administrators update personally as to respond to newly discovered risks as soon as possible.

ModSecurity in VPS Hosting

Protection is vital to us, so we install ModSecurity on all virtual private servers which are set up with the Hepsia Control Panel by default. The firewall can be managed via a dedicated section in Hepsia and is switched on automatically when you include a new domain or generate a subdomain, so you'll not have to do anything by hand. You shall also be able to deactivate it or turn on the so-called detection mode, so it shall keep a log of potential attacks you can later examine, but won't stop them. The logs in both passive and active modes contain information regarding the form of the attack and how it was prevented, what IP address it originated from and other important info that could help you to tighten the security of your websites by updating them or blocking IPs, for example. Besides the commercial rules which we get for ModSecurity from a third-party security firm, we also implement our own rules as every now and then we discover specific attacks that are not yet present in the commercial package. That way, we can easily boost the protection of your VPS promptly as opposed to awaiting a certified update.

ModSecurity in Dedicated Web Hosting

If you opt to host your sites on a dedicated server with the Hepsia CP, your web applications will be protected right away because ModSecurity is provided with all Hepsia-based plans. You'll be able to manage the firewall without difficulty and if necessary, you will be able to turn it off or switch on its passive mode when it will only maintain a log of what's going on without taking any action to prevent potential attacks. The logs which you'll find in the exact same section of the CP are extremely detailed and contain data about the attacker IP, what site and file were attacked and in what ways, what rule the firewall employed to stop the intrusion, etc. This info shall permit you to take measures and increase the protection of your Internet sites even more. To be on the safe side, we use not just commercial rules, but also custom-made ones which our administrators include when they detect attacks which have not yet been included in the commercial pack.